Connecting MX95 HA

ImNoEngineer
New here

Connecting MX95 HA

I'm going to be setting up new Meraki MX95 with HA set up. So here's ideally how the connections will be

ImNoEngineer_0-1703019431096.png

 

This is based off Meraki Documentation on it

ImNoEngineer_1-1703019472671.png

I've set up a test network to download firmware and to test the failover. Right now, we have a single meraki mx80 and i created a test network and added the two Mx95 to it and i connected them to two lan ports on the MX80 so it would connect to internet. 

 

As well, there are two access switches that connects to ports 2/3 and so i had mx95 connections on ports 4/5. So the issue i ran into and i think i have an idea as to why i ran into it, was that the mx95 showed as dual active on both so i added a connection directly between the two Mx95 and it showed active/passive. My assumption is that even though the downstream switches were connected via ports 2/3 and the mx95 on ports 4/5, the vrrp can't go through the mx95 UNLESS the downstream switches are attached to THEIR lan ports and not the LAN ports on the mx80. Hopefully I'm correct in that assumption. Thanks for reading and possibly answer a seemingly simple question

3 Replies 3
KarstenI
Kind of a big deal
Kind of a big deal

Hmm, at least I don’t understand the setup that gives you this problem. Here, a diagram would be helpful. But the setup from the design will definitely work. But there are alternatives:

https://cyber-fi.net/index.php/2022/03/13/how-to-connect-the-meraki-mx-to-ms-switches/

Sorry here's one.

 

ImNoEngineer_1-1703021861429.png

 

 

So disregard the labeling in the image for the bottom two switches. So the two switches connect to ports 2/3 LAN ports on the MX80 (our current mx) I made a test network and connected the two MX95 to ports 4/5 on the MX80. I enabled HA using mx uplinks. However, they both showed active. I resolved this issue by directly connecting them and i was able to test the failover. I think my issue began because i assumed that because the downstream switches and the mx95 were all on the LAN ports on the MX80 that the MX95s would see the VRRP somehow but it does not seem to be the case. So in my initial post, the Warm spare should show correclty, since i'll have the down stream switches connected on the MX95 LAN ports.

 

 

Now I get it. The HA communication is done on the LAN ports, not the WAN ports. Without the direct connection you don't have any "LAN", but with the cable you kind of simulated this.

Later, when your internal switches are in place, it will behave as now with the direct connection.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels